Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or allowlist controls. | |
| Title | HCL BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-01-23T14:53:30.106Z
Reserved: 2024-07-29T21:32:05.157Z
Link: CVE-2024-42183
Updated: 2025-01-23T14:53:24.285Z
Status : Deferred
Published: 2025-01-23T02:15:35.933
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-42183
No data.
OpenCVE Enrichment
No data.